Nefilim

Malware Profile Updated 3 months ago
Download STIX
Preview STIX
Nefilim is a malware, specifically a ransomware, that has been responsible for significant cyber threats globally. It infiltrates systems through suspicious downloads, emails, or websites and can steal personal information, disrupt operations, or hold data hostage for ransom. Between 2019 and 2021, Nefilim was linked to various Ransomware-as-a-Service (RaaS) schemes, including JSWorm, Karma, Nemty, and its own RaaS program. Alongside Clop, Nefilim accounted for the highest number of ransomware family detections during this period, with Crysis and Doppelpaymer following behind. Notably, Nefilim was also Africa's most prevalent banking malware from January to April 2021. The Nefilim ransomware has been associated with several high-profile cyber incidents. In one instance, the Italian website "Difesa e Sicurezza" reported in October that operators of the Nefilim ransomware had posted a list of files appearing to belong to Luxottica on the dark web. The malware has been observed to drop MegaSync into its normal file path under its standard name, with adversaries executing renamed instances of Mega during incident response engagements related to Nefilim and other ransomware families like Sodinokibi, Pysa, and Conti. Behind Nefilim's operations is farnetwork, a notorious entity involved in several ransomware projects since 2019, including JSWorm, Karma, Nemty, and Nefilim itself. Farnetwork, known by multiple handles such as farnetworkl, jingo, jsworm, razvrat, piparkuka, and farnetworkit, helped develop ransomware and manage the RaaS programs for these projects before launching their own RaaS program based on Nokoyawa ransomware in 2022. The Nefilim's RaaS program alone accounted for over 40 victims, with Nokoyawa's dedicated leak site containing information about 35 victims.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Nemty
3
Nemty is a type of malware, specifically ransomware, that infiltrates systems to exploit and damage them. It was developed by a cybercriminal group known as farnetwork, which has been active since 2019. Farnetwork has been involved in several ransomware projects, including JSWORM, Nefilim, Karma, an
Jsworm
3
JSWorm is a type of malware, specifically ransomware, that was active from 2019 to 2021. This malicious software was developed and operated by a threat actor known as 'farnetwork', who has used various aliases including farnetworkl, jingo, jsworm, razvrat, piparkuka, and farnetworkit. Farnetwork gai
Nokoyawa
1
Nokoyawa is a notorious malware, particularly known for its ransomware capabilities. It has been associated with various other malicious software including Quantum, Royal, BlackBasta, Emotet, IcedID, CobaltStrike, SVCReady, CargoBay, Pushdo, Minodo, DiceLoader, AresLoader, LummaC2, Vidar, Gozi, Cany
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
RaaS
Africa
Malware
Data Leak
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
FarnetworkUnspecified
2
Farnetwork, a notorious malware operator identified by cybersecurity researchers from Group-IB, has been active in the cybercrime scene since 2019. Known for deploying five different strains of ransomware, including its proprietary strain Nokoyawa, Farnetwork has collaborated with other cybercrimina
ContiUnspecified
1
Conti is a type of malware, specifically ransomware, known for its ability to disrupt operations, steal personal information, and hold data hostage for ransom. The malicious software infiltrates systems via suspicious downloads, emails, or websites, often unbeknownst to the user. It has been used in
PysaUnspecified
1
Pysa is a type of ransomware, a malicious software designed to exploit and damage computer systems by encrypting data and demanding ransom for its decryption. The Pysa ransomware group, known for its organizational hierarchy that includes senior executives, system admins, developers, recruiters, HR,
ClopUnspecified
1
Clop is a notorious malware, short for malicious software, known for its disruptive and damaging effects on computer systems. It primarily infiltrates systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, Clop can steal personal information, disrupt o
DoppelpaymerUnspecified
1
DoppelPaymer is a form of malware, specifically ransomware, known for its high-profile attacks on large organizations and municipalities. Originally based on the BitPaymer ransomware, DoppelPaymer was reworked and renamed by the threat group GOLD HERON, after initially being operated by GOLD DRAKE.
FarnetworkitUnspecified
1
Farnetworkit, a malicious software or malware, has been active since 2019 under various aliases such as farnetworkl, jingo, jsworm, razvrat, piparkuka, and farnetwork. This cybercriminal entity has been involved in several ransomware projects including JSWORM, Karma, Nemty, and Nefilim. Farnetworkit
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
SodinokibiUnspecified
1
Sodinokibi, also known as REvil, is a significant threat actor first identified in April 2019. This ransomware family operates as a Ransomware-as-a-Service (RaaS) and has been responsible for one in three ransomware incidents responded to by IBM Security X-Force in 2020. The Sodinokibi ransomware st
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Nefilim Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
InfoSecurity-magazine
9 months ago
Threat Actor Farnetwork Linked to Five Ransomware Schemes
Secureworks
a year ago
Ransomware Evolution
CERT-EU
a year ago
80+ Africa Cybersecurity Statistics and Trends (2023)
Securityaffairs
a year ago
2021 data breach exposed data of 70 Million Luxottica customers
MITRE
a year ago
Rclone Wars: Transferring leverage in a ransomware attack
CERT-EU
9 months ago
Prolific ransomware crook spills the beans on several operations
DARKReading
9 months ago
Ransomware Mastermind Uncovered After Oversharing on Dark Web
CERT-EU
9 months ago
Russian-speaking threat actor "farnetwork" linked to 5 ransomware gangs